Skip to main content

Vulnerability disclosure

Roasthubs operates a coordinated vulnerability disclosure (CVD) process for security issues in our products. This page is the customer-facing summary. The full policy lives in the application repository (SECURITY.md).

How to report

Email info@roasthubs.com with a description of the issue, affected product or component, and steps to reproduce where possible.

Do not use public support channels or public issue trackers for unfixed security vulnerabilities.

What we commit to

  • Acknowledgement within 5 business days
  • Coordinated disclosure typically within about 90 days, by mutual agreement
  • Good-faith research within scope is welcomed; see the full policy for safe-harbor language and out-of-scope activities

Scope (summary)

In scope: roasthubs-os, and the Roasthubs edge server stack (Docker Compose on Welotec IPC and equivalent deployments we ship or maintain).

Out of scope: social engineering, disruptive denial-of-service, attacks on customer OT/networks without permission, and third-party systems we do not operate.

CRA contact address

Under the EU Cyber Resilience Act, manufacturers must make a contact address available for reporting vulnerabilities. For Roasthubs products, use:

Internal incident handling (triage levels, CRA reporting timelines) is documented in our Security Incident policy (Notion; may require access).